CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-2302

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

    Published: 15 May 2008
    7.8
    High

    CVE-2008-1749

    Last Modified: 23 Apr 2026

    Memory leak in Cisco Content Switching Module (CSM) 4.2(3) up to 4.2(8) and Cisco Content Switching Module with SSL (CSM-S) 2.1(2) up to 2.1(7) allows remote attackers to cause a denial of service (memory consumption) via TCP segments with an unspecified combination of TCP flags.

    Published: 14 May 2008
    10
    Critical

    CVE-2008-2214

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long community string in an SNMP TRAP packet.

    Published: 14 May 2008
    5
    Medium

    CVE-2008-2215

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/yopy_sync.php and (2) system-logger/print_logs.php.

    Published: 14 May 2008
    9
    Critical

    CVE-2008-2216

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2217

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_imgpath parameter.

    Published: 14 May 2008
    10
    Critical

    CVE-2008-2221

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2222

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2223

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2225

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands via the systemId parameter.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2219

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2224

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _saz[settings][site_dir] parameter to layouts/default/header.saz.php and the (2) _saz[settings][site_url] parameter to admin/alayouts/default/pages/login.php.

    Published: 14 May 2008
    5
    Medium

    CVE-2008-2218

    Last Modified: 23 Apr 2026

    Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2220

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[LANGUAGE_CPATH] parameter to modules/forum/embedforum.php and the (2) CONFIG[BASE_PATH] parameter to modules/scorm/lib.inc.php, different vectors than CVE-2006-4448.

    Published: 14 May 2008
    9.3
    Critical

    CVE-2008-2228

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.

    Published: 14 May 2008
    5
    Medium

    CVE-2008-2226

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2227

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2189

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2190

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported that 5.0 and earlier are also affected.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2191

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_term action to index.php.

    Published: 14 May 2008
    10
    Critical

    CVE-2008-2192

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into box/MiniChat/data/shouts.php via the shout parameter.

    Published: 14 May 2008
    6.5
    Medium

    CVE-2008-2195

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2197

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2198

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2201

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Recipe 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) header, (2) header2, (3) header3, (4) header4, (5) header5, (6) header6, (7) header7, (8) header8, and (9) header9 parameters.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2207

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2208

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2209

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Greeting 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script and (2) msg_script2 parameters.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2205

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2213

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Links 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2200

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2211

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Guestbook 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2194

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2203

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2206

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search action to index.php, and the (2) msg_script parameter to admin/inc/footer.php.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2212

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Cart 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_adminheader, (2) msg_adminheader2, (3) msg_adminheader3, (4) msg_adminheader4, and unspecified other parameters to admin/inc/header.php; the (5) msg_script3 and unspecified other parameters to admin/inc/footer.php; and the (6) keywords parameter to index.php in a search action.

    Published: 14 May 2008
    7.5
    High

    CVE-2008-2193

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2196

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-2199

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in kmitaadmin/kmitam/htmlcode.php in Kmita Mail 3.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2202

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2204

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Search 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) header, (2) header2, (3) header3, (4) header4, (5) header5, (6) header6, (7) header7, (8) header8, and (9) header9 parameters.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2210

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Support 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script, (2) msg_script2, and (3) msg_script3 parameters to admin/inc/footer.php; and the (4) msg_script2 parameter to admin/inc/header.php.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-1419

    Last Modified: 23 Apr 2026

    Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.

    Published: 14 May 2008
    9.3
    Critical

    CVE-2008-1423

    Last Modified: 23 Apr 2026

    Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.

    Published: 14 May 2008
    4.3
    Medium

    CVE-2008-2009

    Last Modified: 23 Apr 2026

    Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

    Published: 14 May 2008
    6.8
    Medium

    CVE-2008-1420

    Last Modified: 23 Apr 2026

    Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.

    Published: 14 May 2008
    10
    Critical

    CVE-2008-1922

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.

    Published: 13 May 2008
    9.3
    Critical

    CVE-2008-0119

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."

    Published: 13 May 2008
    5
    Medium

    CVE-2008-1437

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.

    Published: 13 May 2008
    6.5
    Medium

    CVE-2008-2174

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related to "various areas where security was missing."

    Published: 13 May 2008